Remote Code Execution Vulnerability in Moxa ThingsPro IIoT Gateway
CVE-2018-18396

9.8CRITICAL

Key Information:

Vendor
Moxa
Vendor
CVE Published:
19 October 2018

Summary

Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1 is vulnerable to remote code execution, allowing unauthorized attackers to execute arbitrary code within the context of the application. This flaw could enable an attacker to gain control over affected systems, potentially impacting the integrity and availability of critical network devices.

Affected Version(s)

ThingsPro IIoT Gateway and Device Management Software Solutions 2.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.